Uploaded image for project: 'Lustre'
  1. Lustre
  2. LU-17624

SSK cannot be set up on a FIPS-enabled client

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Minor
    • Lustre 2.16.0
    • Lustre 2.16.0
    • 3
    • 9223372036854775807

    Description

      When trying to setup SSK on a FIPS enabled client we get:

      # lgss_sk -t client -m /ssk_dir/testfs.server.key
      Generating DH parameters, this can take a while...
      error: cannot generate DH parameters
      

      Adding more debug traces, we can see:

      error:050C90CA:Diffie-Hellman routines:DH_generate_parameters_ex:non FIPS method
      

      In FIPS mode, only certain crypto methods are allowed.

      Attachments

        Activity

          People

            sebastien Sebastien Buisson
            sebastien Sebastien Buisson
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: